Top

CertiK says attacker exploited legacy MakerDAO auction flaw to steal 200 ETH

October 08, 2026, 2:54 AM
A legacy auction management contract tied to MakerDAO, now SKY, was exposed in an attack that drained 200 ETH worth more than $500,000, CertiK said. The blockchain security firm identified the cause as missing access controls on the 0x8804d1de function in the contract’s implementation. According to CertiK, the contract still held four unsettled 50 ETH transactions linked to the March 2020 “Black Thursday” liquidation event, when the assets were won with $0 bids. The attacker then moved the stolen funds to Tornado Cash in 10 ETH increments, CertiK said.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading